Add worktree-local Intent policy overlays
Nessuno ha ancora preso questa issue.
Valutazione
- Difficoltà
- 5/5
- Tempo stimato
- Più di una settimana
- Idoneità per principianti
- 42/100
- Tipo di issue
- Funzionalità
- Chiarezza
- Abbastanza chiara
- Stato di attività
- Attiva
- Stack tecnologico
- typescript
- Ambito
- authorization, cli, security
Direzione di ricerca
Inizia tracciando il percorso delle policy esistente di package.json e i consumer di effective-policy indicati nell’issue: list, load, stale, diagnostica di supporto, install --map e hook. Implementa e verifica il resolver protetto di .intent/config.local.json in modo che il tracciamento Git e i controlli di ignoranza esatta, la validazione, la compilazione dei selettori, le esclusioni, il comportamento di migrazione e la precedenza delle policy condivise corrispondano ai criteri di accettazione.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Descrizione
Problem
Intent policy is currently shared through package.json. A user cannot add worktree-local grants or denials without changing committed repository policy. Local state also needs strict Git safety rules so it cannot be silently tracked or hide .intent/hooks.
User outcome
A user can manually create a valid .intent/config.local.json beside the nearest owning package.json. Intent applies it automatically as personal worktree state: local skills can broaden shared defaults, local excludes can add denials, and shared excludes remain final.
Example:
{
"skills": [
"@acme/private-skill"
],
"exclude": [
"@acme/unsafe-skill"
]
}
In scope
- Add
.intent/config.local.jsondiscovery beside the nearest owningpackage.jsonas the sole local policy source. Keeppackage.jsonas the sole shared committed source. - Provide reusable guarded local resolver and storage behavior that future installer or review work may consume.
- Require local policy operations to run in a Git worktree. Use only the exact sidecar path in
$GIT_COMMON_DIR/info/exclude; do not ignore.intent/, and preserve.intent/hooks. - Check that the exact local path is untracked on every local read and write. Reject tracked paths even when
info/excludecontains the path. - Support a top-level JSON object with optional
skillsandexcludefields, where at least one field is present. Parse present fields strictly as arrays of valid strings under the existing selector and exclusion grammars. - Activate a manually created valid local file automatically. Fail closed when a present local file is tracked, unreadable, malformed, or not exactly ignored.
- Compile shared and local skill selectors independently. For declared shared policy, grant a candidate when either predicate matches. Preserve existing package, exact-skill, wildcard, npm, and workspace semantics.
- Preserve migration behavior when shared
intent.skillsis absent and localskillsis omitted or[]. A non-empty localskills, including["*"], ends that migration mode. - Apply shared and local exclusions as final additive denials. Local policy must never restore a skill denied by shared policy.
- Make all policy consumers use the same effective-policy resolver: list, load, stale, support diagnostics, install
--map, and hooks.
Acceptance criteria
- A valid manual
.intent/config.local.jsonbeside the nearest owningpackage.jsonis discovered and applied automatically in a Git worktree. - The local file is accepted only when the exact path is untracked and exactly ignored through
$GIT_COMMON_DIR/info/exclude; the check applies to both reads and writes. .intent/hooksremains usable, and the implementation never ignores.intent/as a whole directory.- A tracked, unreadable, malformed, or not-exactly-ignored present local file fails closed with actionable diagnostics.
- The local object rejects unknown top-level fields, accepts only optional
skillsandexclude, requires at least one of them, and validates each present array under existing selector or exclusion rules. - Shared and local selector sets are compiled independently. For declared shared policy, a candidate is granted when either set matches without changing package, exact-skill, wildcard, npm, or workspace semantics.
- Shared and local exclusions both deny matching candidates after grant selection. A shared exclusion cannot be bypassed locally.
- When shared
intent.skillsis absent, omitted or empty localskillspreserves current migration behavior. A non-empty localskills, including["*"], ends it. list,load,stale, support diagnostics, install--map, and hooks resolve the same effective policy and report local-source provenance where they already report policy diagnostics.- The work introduces no
.intent/config.json, global local-policy store, new dependency, destination-selection UI, preview, confirmation, package writing, content delivery, locks, hashes, or Git skill-source support.
Related work
Blocked by: None. #219 is completed prior behavior. #220 and #221 may integrate local policy when available but can proceed independently with package.json-only behavior. #222 independent.
#220 owns interactive destination selection if and when it integrates local configuration. #221 owns repeat review if and when it integrates local configuration.
- Lingua principale
- TypeScript
- Stelle
- 331
- Fork
- 22
- Merge medio
- 12h 17m
- PR unite (30g)
- 51
Guida per i contributori
Apri la guida per i contributori
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Altre issue di TanStack/intent
-
Difficoltà 5/5 Più di una settimana Idoneità per principianti 45/100
-
Difficoltà 4/5 3-5 giorni Idoneità per principianti 48/100
-
Difficoltà 5/5 Più di una settimana Idoneità per principianti 35/100
-
Difficoltà 5/5 Più di una settimana Idoneità per principianti 45/100
-
enhancement
Difficoltà 5/5 Più di una settimana Idoneità per principianti 35/100
Tutte le issue di TanStack/intent
Issue simili
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 75/100
safetrustcr/dApp-SafeTrust#426 ·
-
area:workflow bug ready-for-agent
Difficoltà 2/5 1-3 ore Idoneità per principianti 75/100
fil-donadoni/tolaria#4409 ·
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 70/100
Fission-AI/OpenSpec#1960 ·
-
Add dependabot Aperta
Difficoltà 2/5 1-3 ore Idoneità per principianti 70/100
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 75/100
corsairdev/corsair#1764 ·